Re: Firewall Policy



mhyasseen@xxxxxxxxx wrote:
I am an undergraduate student. I have a project related to the
firewall policy. Although I have got some material, I required some
more reference regarding the following topics. Any help would be
appreciated.
(1) What will be size of the firewall policy for an enterprise
network.

This question doesn't make any sense. What do you mean by "size of the
firewall policy"?

(2) What rules in general contain in the rule set i.e., accept. or
deny

Both.

(3) What are rules which are at the top of the rule set and which one
are the end of the rule set,

That entirely depends on your particular requirements. Firewalls don't
come as "one size fits all" solutions.

(4) and why the rules at the bottom of the ruleset have the lowest
priority than the rules at the top of the ruleset.

Because the rules on top match first (normally, that is).

Read a good book on firewalls (e.g. [1]), and make sure you have at
least a basic understanding of networking before you do.

[1] http://www.oreilly.com/catalog/fire2/

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich
.



Relevant Pages

  • RE: CheckPoint remote access
    ... It sounds like the firewall policy is getting in your way. ... unload the locally installed policy. ... Connect notebook directly to ethernet port with IP ...
    (Security-Basics)
  • ISA 2004 - Not processing rule?
    ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
    (microsoft.public.isa)
  • ISA 2004 - Not processing rule?
    ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
    (microsoft.public.isa.configuration)
  • Re: How to find NATed address
    ... > NAT workarounds. ... > response from company Splortsoft who tells me that their ... > to defeat local firewall policy - after all, ... > Splortsoft allows malicious contravention of firewall policy ...
    (comp.security.firewalls)
  • ISA 2004 - Not processing rule?
    ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
    (microsoft.public.isaserver)